In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
https://friends-of-presta.github.io/security-advisories/modules/2023/05/25/scfixmyprestashop.html